Microsoft's 2026 Digital Defense Report puts the median time from discovery to weaponization below a day, while enterprises still take 30 to 60 days to fix critical external flaws. Sysdig and Black Kite document JADEPUFFER, the first ransomware operation run end to end by an AI agent.
Key Takeaways
Security teams have long been told that machine-speed attacks were coming. As of this month, they have a case file. Microsoft's annual threat report, published October 1, describes an environment where the gap between a flaw becoming known and a working exploit is now measured in hours, and where AI agents have begun running the entire attack chain with little human direction. The patch calendar most enterprises work to was built for a slower adversary.
The 2026 Microsoft Digital Defense Report says the median time from a vulnerability being discovered in the wild to being weaponized has fallen to well below 24 hours, while critical external vulnerabilities typically take enterprises 30 to 60 days to remediate. Volume compounds the problem: nearly 40,000 CVEs were published in the first half of 2026, putting the year on track to roughly double. Microsoft's research leads, Tanmay Ganacharya and Wes Malaby, summarize it bluntly: "AI is changing the physics of cybersecurity."
Identity remains the other main door. According to TechTimes' breakdown of the report, which covers July 2025 through June 2026, phishing accounted for 23% of observed intrusions, up from 7% the year before, and exploits of public-facing applications rose to 24% from 15%. Once inside on a valid account, attackers went on to harvest further credentials in 52.2% of cases. Microsoft also describes a controlled evaluation in which an AI model strung together 32 consecutive attack steps to reach full domain compromise.
The case that turns those projections into evidence came from Sysdig's Threat Research Team, which documented JADEPUFFER on July 1 as the first agentic ransomware operation. The agent entered through an internet-facing Langflow instance using CVE-2025-3248, an unauthenticated remote code execution flaw, then harvested cloud and AI provider credentials, found object storage still running on default credentials, and pivoted to a production configuration service through CVE-2021-29441, a years-old Nacos authentication bypass. It extracted 1,342 configuration items, encrypted them with a key it never stored, dropped the original tables, and left a ransom table in their place.
The tell was the speed and the self-correction. When a login attempt failed, the agent diagnosed the cause and shipped a corrected payload 31 seconds later. When a server returned XML instead of the JSON it expected, the next payload simply included an XML parser. Its code carried natural language comments explaining why it was prioritizing the largest database. Michael Clark, Sysdig's Director of Threat Research, wrote that "the skill floor for running ransomware has dropped to whatever it costs to run an agent."
The same actor appears in the cloud. Security Affairs reports that Microsoft, which tracks the group as Storm-3168, traced an Azure intrusion to two compromised service principals. Their credentials had been posted in plaintext in a public GitHub issue and later edited out, yet remained visible in the edit history. After 15.5 hours of quiet reconnaissance, the attacker ran more than 150 destructive or credential operations in 35 minutes, targeting over 100 storage accounts, a Key Vault, and a Function App. The core deletion took about seven minutes. Resource locks and deletion protection were what saved several of the storage accounts.
Black Kite's 2026 Ransomware Report counted 7,551 publicly disclosed victims between April 2025 and March 2026, a 24.9% rise and the fourth straight annual record, and also names JADEPUFFER as the first agentic ransomware. Its more useful finding is about warning signs: 93.5% of victims showed a meaningful spike in Black Kite's ransomware susceptibility score before their disclosure appeared, and 85.9% showed a month-over-month increase of 10% or more. The weaknesses also outlasted the attack. After the incident, 43.5% of victims still carried a vulnerability rated CVSS 9.0 or higher, and 30.8% still carried a known exploited vulnerability.
Put the sources side by side and the pattern is consistent. JADEPUFFER did not need a novel exploit. It needed an exposed AI tool, a default password, a years-old flaw, and credentials stored where an agent could read them. Those are the same gaps a monthly patch cycle and an annual access review leave open, and an agent that works around the clock finds them first. The defensive answer is less about matching the attacker's speed than about removing what it can reach in those first minutes.
The first autonomous ransomware case did not break anything that was well defended. It walked through doors that were already open, faster than any human crew could, and that is the measure every exposed system now has to meet.
Whitepaper
JADEPUFFER got in through a running Langflow server and lifted the AI provider keys stored on it. This whitepaper covers the runtime telemetry that exposes a compromised AI workload and how to contain one once it has turned.
Download
Guide
When the core deletion in Microsoft's Azure case took about seven minutes, there is no time to write a plan mid-incident. This kit sets out the first-hour containment, evidence, and notification steps to agree on beforehand.
Download
Whitepaper
If exploits arrive within a day and patches take 30 to 60, inline prevention and egress control have to cover the gap. This whitepaper explains the inspection and application controls that can block an exposed service before it is fixed.
Download
SpyCloud's survey of 750 security leaders found 53% of organizations see malware only on managed devices.
Unit 42 found only 12 of 405 AI-enabled malware samples on a real production endpoint, with roughly 97% never leaving sandboxes and VirusTotal.
Unit 42 found encryption present in just 78% of 2025 extortion cases, and the fastest attacks now exfiltrate in 72 minutes.